26 June 2023

Briton sentenced to 5 years in prison for the 2020 Twitter hack


Briton sentenced to 5 years in prison for the 2020 Twitter hack

A British man was sentenced to five years in prison for his involvement in the 2020 Twitter hack, one of the biggest hacks in social media history that compromised numerous accounts of celebrities and politicians, including former US President Barack Obama and Microsoft’s Bill Gates.

Joseph James O'Connor, 24, known as PlugwalkJoe, was extradited to the US from Spain on April 26, 2023. He pleaded guilty in a US court on May 9, 2023.

In 2020, O'Connor and unnamed co-conspirators gained access to Twitter’s administrative tools and hijacked several accounts belonging to major companies and celebrities. They then used the compromised accounts to promote a Bitcoin scam that raked in almost $120,000.

According to court documents, between March and May 2019, PlugwalkJoe together with his partners in crime carried out a SIM swapping scheme to gain access to three executives working at a cryptocurrency exchange. They gained unauthorized access to multiple companies accounts and computer systems and stole approximately $784,000 in cryptocurrency.

PlugwalkJoe also faces three years of supervised release after serving his prison term. He has also been ordered to forfeit $794,000.

Back to the list

Latest Posts

Cyber Security Week in Review: December 20, 2024

Cyber Security Week in Review: December 20, 2024

In brief: A suspected Russian cyberattack hits Ukraine's state registries, new ICS malware targets Mitsubishi and Siemens systems, and more.
20 December 2024
Major phishing campaign abuses HubSpot to steal credentials from European firms

Major phishing campaign abuses HubSpot to steal credentials from European firms

The attackers exploited the service’s legitimate functionality to create convincing phishing pages.
19 December 2024
UAC-0125 malware campaign targeting Ukrainian military personnel

UAC-0125 malware campaign targeting Ukrainian military personnel

Victims are lured to fraudulent websites offering to download a malicious version of the Army+ app.
19 December 2024